
Yournotify Security & Risk Analysis
wordpress.org/plugins/yournotifyYournotify WP plugin with integration for WooCommerce and features to support SMTP, drip campaigns, and more for email & SMS marketing.
Is Yournotify Safe to Use in 2026?
Generally Safe
Score 100/100Yournotify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yournotify" plugin v2.1.7 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, a high percentage of properly escaped output, and a lack of dangerous functions, file operations, or bundled libraries. The vulnerability history is also clean, indicating a generally well-maintained plugin. However, there are significant concerns regarding the attack surface, particularly the presence of multiple unprotected entry points.
Specifically, the analysis reveals 10 AJAX handlers with 5 lacking authentication checks and 8 REST API routes with 1 missing permission callbacks. While no critical or high-severity taint flows were identified, the "flows with unsanitized paths" are a concern as they could potentially lead to vulnerabilities if exploited, even if not immediately critical. The lack of nonce checks on some AJAX handlers is a common oversight that can be exploited for cross-site request forgery (CSRF) attacks. The vulnerability history, while currently empty, does not guarantee future security, and the identified unprotected entry points remain a primary risk.
In conclusion, "yournotify" v2.1.7 has strengths in its code hygiene for database interactions and output handling. However, the substantial number of unprotected AJAX handlers and REST API routes presents a significant risk. Developers should prioritize implementing proper authentication and permission checks on all exposed endpoints to mitigate potential exploits. The identified unsanitized paths also warrant investigation and remediation.
Key Concerns
- Unprotected AJAX handlers
- REST API route without permission callback
- Flows with unsanitized paths
Yournotify Security Vulnerabilities
Yournotify Release Timeline
Yournotify Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Yournotify Attack Surface
AJAX Handlers 10
REST API Routes 1
Shortcodes 3
WordPress Hooks 24
Scheduled Events 2
Maintenance & Trust
Yournotify Maintenance & Trust
Maintenance Signals
Community Trust
Yournotify Alternatives
Newsletter Subscription Form – User Subscriptions Form, Capture Email
newsletter-subscription-form
Newsletter Subscription Form for WordPress is the ultimate lead generation, customer acquisition and email marketing plugin to grow and engage your ma …
Mailchimp Widget by ProteusThemes
proteusthemes-mailchimp-widget
Capture your visitor's email address and subscribe them to your newsletter campaign with this simple Mailchimp widget plugin!
Email Subscribers – Group Selector
email-subscribers-advanced-form
Add-on for Email Subscribers plugin using which you can provide option to your users to select interested groups in the Subscribe Form.
WOW Mailchimp Widget
wow-mailchimp-widget
This plugin is Mailchimp newsletter widget. And can be used as subscription form in all supported widget areas of theme. Use you API Key and List Id t …
MC4WP: Mailchimp for WordPress
mailchimp-for-wp
The #1 Mailchimp plugin for WordPress. Allows you to add a multitude of newsletter sign-up methods to your site.
Yournotify Developer Profile
1 plugin · 0 total installs
How We Detect Yournotify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yournotify/assets/css/main.css/wp-content/plugins/yournotify/assets/js/frontend.js/wp-content/plugins/yournotify/assets/js/frontend.jsyournotify/assets/css/main.css?ver=yournotify/assets/js/frontend.js?ver=HTML / DOM Fingerprints
<!-- Yournotify Subscribe Widget -->data-yournotify-emaildata-yournotify-list-idYournotifyVars/yournotify/v1/webhook